Fyndit

Privacy Policy

Last updated 11 luglio 2026

1. Data controller

The controller for the processing described below is Teddy VALENTIN, a French sole trader operating as VALENTIN TEDDY, established at 47 rue Vivienne, 75002 Paris, France. The privacy contact point is contact@fyndit.app. Given the current nature and scale of the processing, appointing a data protection officer is not considered mandatory and no DPO has been appointed. This assessment will be reviewed if the processing changes.

2. Data collected

Depending on how you use the website and service, we may collect:

  • contact and marketing data: email address, language, collection source and date, consent record and date, and opt-out status;
  • account and access data: Discord ID, username, avatar, technical session identifiers and preferences;
  • contract and payment data: plan, subscription status, Whop payment, member or user IDs, and activation or cancellation dates; Fyndit does not receive full bank-card details;
  • data required to operate the SaaS: settings, rules, filters, sessions, regions, favourites, webhooks, action history, logs and technical data;
  • support data: the content of requests and communications with Fyndit;
  • usage and performance data: pages or routes viewed, interface events, date and time, referrer, approximate country or area, browser, operating system and device type.
  • first-party audience measurement: a random first-party identifier, a server-side pseudonymous fingerprint, user agent and navigation path; no advertising profile or cross-site tracking is created.

Fields marked as required are needed to answer a request or create and perform the account or subscription. Without them, the relevant feature may be unavailable. Marketing data is optional.

3. Processing purposes

  • providing the website, creating and administering accounts, authenticating users and operating the SaaS;
  • managing orders, payments, subscriptions, activations, cancellations and the customer relationship;
  • sending the requested guide, service messages and, where permitted, Fyndit offers;
  • providing support, security, fraud prevention and incident response;
  • measuring audience and performance and improving the website and service;
  • meeting legal, accounting and tax duties and establishing, exercising or defending legal claims.

4. Legal bases

  • performance of a contract or pre-contractual steps for accounts, the SaaS, support, orders and subscriptions;
  • consent for electronic marketing sent to prospects and for any non-essential tracker added in the future;
  • Teddy VALENTIN's legitimate interests in securing, administering, measuring and improving the services and offering similar services to customers, subject to the right to object;
  • compliance with legal obligations for accounting, invoicing, tax and responses to authorised public bodies.

5. Storage locations

Supabase hosts marketing email addresses and certain account, order and authentication data. OVHcloud hosts application infrastructure and the more detailed user information required to operate the SaaS. Vercel hosts the website, its web functions and related audience and performance data.

The configured hosting regions and processor data flows are reviewed periodically.

6. Recipients and providers

To the extent required for their role, data may be accessed by Teddy VALENTIN and the following recipients:

  • Whop — checkout, payments and subscription management;
  • Discord — sign-in, account identity and certain service features;
  • Supabase — database and technical services;
  • OVHcloud — application infrastructure and data hosting;
  • Vercel — website hosting, web functions, audience and performance measurement;
  • NIGHTPASS, SAS au capital de 2 000 euros, SIREN 938 865 441, RCS Bordeaux 938 865 441, at 21 rue Maurice Herzog, 33810 Ambès, France — assists Teddy VALENTIN in promoting Fyndit and running marketing campaigns. NIGHTPASS should receive only the contact, campaign and consent data needed for that role and may not use it for its own marketing without a separate legal basis;
  • professional advisers and administrative or judicial authorities where required by law or necessary to defend legal rights.

Personal data is not sold.

7. Retention period

  • prospects and marketing subscribers: until consent is withdrawn or an objection is made, and no later than three years after collection or the last active contact; minimal suppression-list data may be retained to honour the opt-out;
  • account and operational SaaS data: for the contractual relationship, followed by deletion or restricted archiving of necessary evidence for up to three years, unless another statutory period applies;
  • order, payment and billing data: for the contractual relationship, with accounting records archived for ten years;
  • support data: for the time required to resolve the request, then for up to three years after closure where needed for follow-up or evidence;
  • technical and security logs: up to 12 months, unless an incident or legal duty justifies longer retention;
  • dashboard session: 30 days; temporary OAuth sign-in data: 10 minutes;
  • Discord invitation-click attribution: up to 12 months;
  • first-party campaign-attribution cookies: 90 days; when attribution is associated with a lead or order, it follows that record's retention period;
  • first-party audience-measurement identifier and events: no more than 13 months, then deletion or aggregation; user agents are kept within the same limit;
  • Vercel Analytics data: aggregated statistics; Vercel discards its calculated visitor identifier after 24 hours.

Data is then deleted or anonymised unless the law or an ongoing claim requires continued retention.

8. Your rights and how to exercise them

Subject to the GDPR and French Data Protection Act, you may request access, rectification, erasure, restriction or portability of your data. You may object to processing based on legitimate interests and withdraw consent at any time without affecting prior lawful processing.

To exercise a right or request complete deletion of data that may lawfully be deleted, email contact@fyndit.app and identify the relevant email address or account ID. Identity evidence will be requested only where there is reasonable doubt. We normally respond within one month; this may be extended by two months for a complex request, in which case you will be informed.

Erasure is not absolute: some data may be retained to meet accounting, tax or legal duties or to establish, exercise or defend legal claims.

You may also complain to the CNIL at 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or https://www.cnil.fr.

9. Cookies and trackers

Fyndit may use cookies and similar technologies, including browser local storage, to operate the website and Service, remember certain choices and understand website usage in aggregate.

  • strictly necessary cookies: technical operation, request routing, security and abuse prevention;
  • authentication cookies: Discord sign-in, session maintenance and secure dashboard access;
  • preference cookies: remembering language and certain display choices;
  • first-party attribution cookies: remembering the first and latest campaign source, entry page and referring domain to attribute sign-ups and orders, without tracking across websites;
  • first-party audience-measurement cookie: a random identifier limited to Fyndit, used to deduplicate visitors and connect their pages and clicks; it can be refused on this page;
  • functional local storage: remembering completed actions, such as dismissing a prompt, so it is not displayed again unnecessarily;
  • audience and performance measurement: aggregated statistics about viewed pages, interactions, devices and technical performance, without cross-site advertising tracking in the current configuration.

Fyndit uses Vercel Web Analytics and Speed Insights for aggregated audience and performance measurement. In the current configuration, these tools are not used to track a person for advertising across multiple websites.

Detailed first-party measurement is based on a legitimate interest in administering and improving the website. Fyndit generates the identifier randomly and does not store its raw value in the database: only an HMAC fingerprint is retained. Fyndit does not perform hardware or canvas browser fingerprinting. An objection mechanism is provided below.

Cookies strictly necessary for the Service may be used without consent. Any advertising, social-media or other non-exempt tracker added in the future will be blocked until consent. An interface will then make it equally easy to accept, reject or choose purposes and to change that choice at any time.

10. Unsubscribing and direct marketing

Every marketing email must include a simple, free opt-out. You may also withdraw consent or object to marketing by emailing contact@fyndit.app. Teddy VALENTIN and NIGHTPASS must apply that choice to Fyndit campaigns.

11. Transfers outside the European Economic Area

Some providers, including Vercel, Whop and Discord, are based in the United States or may use subprocessors outside the European Economic Area. Depending on the data flow, transfers rely on an applicable adequacy decision, including the EU–US framework where it covers the recipient, or on the European Commission's Standard Contractual Clauses supplemented by additional measures where needed. Information about applicable safeguards may be requested at contact@fyndit.app.

12. Security and processors

Most data is technically processed and hosted using specialist providers such as Supabase, OVHcloud, Vercel, Whop and Discord. Using those providers does not transfer Teddy VALENTIN's responsibility for processing purposes and means that he determines.

Teddy VALENTIN applies, directly and through those providers, technical and organisational safeguards proportionate to the risks, including access controls, encrypted communications, hashing of certain secrets and identifiers, logging, appropriate backups and restricted permissions. Access to customer data is limited to people and services that need it to operate, secure or support the service.

Providers processing data on Teddy VALENTIN's behalf must be bound by terms meeting Article 28 GDPR. Because no online service can guarantee absolute security, safeguards are reviewed against the risks, the state of the art and changes to the service.

13. Personal-data breaches

Security incidents affecting personal data are assessed, contained, corrected and documented. Where a breach is likely to risk individual rights and freedoms, Teddy VALENTIN notifies the CNIL without undue delay and, where feasible, within 72 hours after becoming aware of it. Affected individuals are informed without undue delay where the breach is likely to create a high risk, unless a statutory exception applies.

14. Automated decisions and minors

Fyndit does not, solely through the processing described in this policy, make decisions that produce legal or similarly significant effects on a person. Product automations execute the User's choices and settings; they are not decisions made by Fyndit about that User.

Paid plans and purchasing features are not intended to be independently purchased by minors. If data was provided without required permission, a legal representative may request deletion at contact@fyndit.app.

15. Changes to this policy

This policy may be updated to reflect changes to the service, providers or applicable law. The last-updated date appears at the top of the page. Material changes will be brought to users' attention by an appropriate means.

You can opt out of first-party audience measurement. This choice is stored for 13 months on this device.